This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Check_lsa7 How Do You Make It Go Away?

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This file has been sitting in my C drive for the past few hours, how the heck do I get rid of it, its really been bothering me, It cannot be deleted, read of moved, I read on another website that it is a file used by people who fish on computers to find passwords and bank information, So If anyone could give me the advice and steps I need to remove this defiant little file that would be much appreciated. Thanks, Josh.
Hello and Welcome to the Forum.


You need to download HJT and post the log HijackThis.


Click the "Save" button.

Please put your HijackThis in it's own folder, (I create a new folder in C:\ named HJT).
You can do a Right Click on any open area on the desktop, New> Folder, then rename the folder HJT.

Open HijackThis and select: Do a system scan and save a log file.

When the scan is finished, Click Edit> Select All> Edit> Copy> and paste its contents here [Add Reply].
Good to meet you man, alright heres the log file. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:59:09 AM, on 9/8/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe C:\Program Files\Messenger\MSMSGS.EXE C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\SoftwareDistribution\Download\eb5ff0ae9fdaa24285c4924997a7aa90\update\update.exe O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Gaming Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe – End of file - 2274 bytes
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.

Open the HijackThis Folder. Find the file HijackThis.exe, Right Click on the file and Select Rename. Rename Hijackthis.exe to Spyware.exe.

Post a new HijackThis Log.

Do you have a anti-virus program?
At the moment I do not have a anti virus program, in the process of acquiring the new norton systemworks from my father. But anyways, I renamed the .exe file and here is the new log. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2:10:04 AM, on 9/9/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\qdiomutv.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe C:\Program Files\Messenger\MSMSGS.EXE C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\Spyware.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: 0 - {29DD30AA-F510-4BAE-4794-33DEAD4908E2} - C:\Program Files\Windows NT\rybimovap228.dll O2 - BHO: (no name) - {85712646-8A2D-4860-8B2A-A7A701016CF0} - C:\WINDOWS\System32\mlljj.dll O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - C:\WINDOWS\system32\qvhdemtb.dll O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Gaming Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: DomainService - - C:\WINDOWS\System32\qdiomutv.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe – End of file - 2858 bytes
Buy yeah, what the heck is the Check_LSA7 File, would you explain to me what on earth this little .txt file is, and is it the reason why my PC is running a little chuggy lately?
I don't see a anti-virus program running or a firewall. Get the free ones.

Click HERE and Save, Install, Update and run a full scan.


Below is a list of some free firewalls (in no order of preference).It is important to note that you should only have one firewall installed at a time, but you can download to your Desktop and install each in turn to see which one you prefer.



Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment
Okay, well, yes the Check_LSA7 is in the C:\ Drive, it just sits outside of all the folders, its exact location is C:\Check_LSA7, I do have a firewall, it is the firewall provided with Window SP2. I will get the AV programs and provide you with the new log file in just a couple of minutes.
I wanted you to do this. That's why I wanted the name and location. We can findout what infection it is.

Please go to http://virusscan.jotti.org , click on Browse, and upload the following file for analysis:

C:\Check_LSA7.txt

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.


If Jotti is too busy you can try these.

http://www.kaspersky.com/scanforvirus.html


http://www.virustotal.com/en/indexf.html
Okay, at the moment AVG is performing a virus scan, using its updated information base or whatever. Well then, basically, a few days ago my computer was hit by a serious spyware attack, and my computer was accessed by someone. I immediatley disconnected it from the internet and tried to remove all the offending files, but unfortunatley I couldn't, and I was forced to perform a complete system reformat. Well as you can see, a new problem has arisen, last night I was on a website called projectplaylist.com looking at music when the computer began to run slow, I went into add remove programs and removed all the ad files that had been installed. That was when I noticed that the same file that had been there when I was attacked the first time, had made its second appearance. I'm doing all that I can to avoid another system reformat, and the conditions of my PC now are no where as to where they were before. The only thing that I have noticed is that the computer is running slightly slower than it used to, slow response times on buttons, Mozilla Firefox takes forever to start up and some programs that I use also take a moment or two to start up. I'm looking for the solution to this, I run programs like Ad-Aware 2007 on a regular basis to remove any threats, but this one stays there, I am unable to edit, delete, and move Check_LSA7 and its bothering me as I am doing all that I can to avoid what had happened before.
Doesn't surprise me. Let the scan do it's thing and we'll see what we have. Be sure to delete any virus' it finds. Don't try any fixes by yourself. By the way, these are bad: I think a version of the Vundo infection. O2 - BHO: 0 - {29DD30AA-F510-4BAE-4794-33DEAD4908E2} - C:\Program Files\Windows NT\rybimovap228.dll O2 - BHO: (no name) - {85712646-8A2D-4860-8B2A-A7A701016CF0} - C:\WINDOWS\System32\mlljj.dll O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - C:\WINDOWS\system32\qvhdemtb.dll On another note: Windows Firewall only checks items coming in. If you already have a bad guy that calls home to a remote server, Windows Firewall won't even see that.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI